NEW: Group Profiler — instant APT intel lookup. Try it →

Inception

G0100 Russia Espionage MITRE ATT&CK →

Also known as: Inception Framework · Cloud Atlas

Overview

Inception is a cyber espionage group active since at least 2014. The group has targeted multiple industries and governmental entities primarily in Russia, but has also been active in the United States and throughout Europe, Asia, Africa, and the Middle East.

Naming & attribution

Inception is tracked under 3 names across the industry. It uses 22 documented ATT&CK techniques — more than 55% of the 174 groups tracked here. Activity attributed since at least 2014.

Who calls this group what — MITRE lists each alias with the report that used it, but not which vendor coined it.
NameFirst reported by
Inception FrameworkSymantec
Cloud AtlasGReAT

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • Sidewinder India — 13 shared techniques (33% overlap)
  • Confucius — 10 shared techniques (32% overlap)
  • APT33 Iran — 11 shared techniques (26% overlap)
  • APT19 China — 9 shared techniques (26% overlap)
  • Higaisa South Korea — 10 shared techniques (25% overlap)
  • BRONZE BUTLER China — 12 shared techniques (24% overlap)

Targets

Government · Private sector

Regions

Afghanistan · Armenia · Azerbaijan · Belarus · Belgium · Czech Republic · Greece · India · Iran · Italy · Kazakhstan · Kenya · Malaysia · Russia · South Africa · Suriname · Turkmenistan · Ukraine · United Kingdom · United States · Vietnam

Capabilities

  • Exploitation of public-facing / client applications — ATT&CK T1203

TTPs — 22 techniques across 9 tactics

Resource Development

Initial Access

Execution

Persistence

Stealth

Credential Access

Collection

Command and Control

Tools & malware (3)

PowerShower · VBShower · LaZagne

Reporting (3)